CVE-2023-20274 is a privilege escalation vulnerability in the installer script of Cisco AppDynamics PHP Agent. It allows an authenticated, local attacker to elevate privileges to root due to insufficient permissions set on the agent's install directory. With a CVSS score of 7.8 (High), this vulnerability is easily exploitable with low attack complexity and no user interaction, leading to high impact on confidentiality, integrity, and availability. There is currently no public exploit code available, nor is it being actively exploited, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21.2.7CPE matchmatch criteria | cpe:2.3:a:cisco:appdynamics:21.2.7:*:*:*:*:*:*:* | ||
21.2.8CPE matchmatch criteria | cpe:2.3:a:cisco:appdynamics:21.2.8:*:*:*:*:*:*:* | ||
21.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:appdynamics:21.4.0:*:*:*:*:*:*:* | ||
21.4.2CPE matchmatch criteria | cpe:2.3:a:cisco:appdynamics:21.4.2:*:*:*:*:*:*:* | ||
21.4.3CPE matchmatch criteria | cpe:2.3:a:cisco:appdynamics:21.4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.